Trojan

Trojan.Win32.KillMBR.gox information

Malware Removal

The Trojan.Win32.KillMBR.gox is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.KillMBR.gox virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Likely installs a bootkit via raw harddisk modifications
  • Attempted to write directly to a physical drive

How to determine Trojan.Win32.KillMBR.gox?


File Info:

name: 406E3203B3A3EE25BEEA.mlw
path: /opt/CAPEv2/storage/binaries/9e30d3007c07085e52cf54e034e02209739c914733f8d93d56974159c5189c4b
crc32: 127CA0D8
md5: 406e3203b3a3ee25beea1e85b8fc4bee
sha1: b0fe440f01ea404daf18a511b3c94df920ea639c
sha256: 9e30d3007c07085e52cf54e034e02209739c914733f8d93d56974159c5189c4b
sha512: e59a0ab294f853fe1b6236998bfb9cade4386a01c0e8da08175339611417638784a39b7474feadbe70d8137e80d63c0099626b5fed63417d8f0ff88a40f268af
ssdeep: 6144:pPO0RWQ+Wu+MlTHr9uc78j1ihZo3bZ5u2N/QClgy:pPOorTmTHr9F7o1U6nu2N/Cy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9A46C20B8C18172EDF320F947ECB53205ADB8F0472599E712D817FAD9582D17A37A9B
sha3_384: b5c66949a4f1804dd508d0ac6f5144d0e3656bac68d262609a6b9ba70313882bfcbf216c5cbb94e57de934fab6c76316
ep_bytes: e9bbe20000e98fce0300e9caa30300e9
timestamp: 2021-11-13 04:05:47

Version Info:

0: [No Data]

Trojan.Win32.KillMBR.gox also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.KillMBR.4!c
MicroWorld-eScanTrojan.GenericKD.38073144
FireEyeGeneric.mg.406e3203b3a3ee25
ALYacTrojan.GenericKD.38073144
ZillyaTrojan.KillMBR.Win32.534
AlibabaTrojan:Win32/KillMBR.25bcaeaf
BitDefenderThetaGen:NN.ZexaF.34294.DKW@aOUFhaai
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0WKR21
KasperskyTrojan.Win32.KillMBR.gox
BitDefenderTrojan.GenericKD.38073144
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.BitCoinMiner.la
Ad-AwareTrojan.GenericKD.38073144
TrendMicroTROJ_GEN.R002C0WKR21
McAfee-GW-EditionBehavesLike.Win32.Generic.gm
SentinelOneStatic AI – Suspicious PE
EmsisoftTrojan.GenericKD.38073144 (B)
APEXMalicious
GDataTrojan.GenericKD.38073144
JiangminTrojan.KillMBR.bl
AviraTR/KillMBR.gkqib
MicrosoftProgram:Win32/Uwamson.A!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.TrojanX-gen.C4777292
McAfeeArtemis!406E3203B3A3
MAXmalware (ai score=88)
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A

How to remove Trojan.Win32.KillMBR.gox?

Trojan.Win32.KillMBR.gox removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment